USN-8721-1: OpenSSH vulnerabilities

Publication date

3 September 2026

Overview

Several security issues were fixed in OpenSSH.


Packages

  • openssh - secure shell (SSH) for secure access to remote machines

Details

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions
between agent locking and the session-bind@openssh.com extension. A remote
attacker with access to a forwarded agent connection could possibly use
this issue to perform operations that should only be available locally,
such as adding tokens or using keys. (CVE-2026-73281)

It was discovered that OpenSSH's ssh client incorrectly handled concurrent
remote-forwarding operations. A remote attacker could possibly use this
issue to cause a use-after-free condition, resulting in a denial of service
or the execution of arbitrary code. (CVE-2026-73282)

It was discovered that OpenSSH's sshd server incorrectly applied the
restrict keyword from authorized_keys to tunnel forwarding requests. A
local attacker with an authorized key could possibly use this issue to
bypass intended tunnel...

It was discovered that OpenSSH's ssh-agent incorrectly handled interactions
between agent locking and the session-bind@openssh.com extension. A remote
attacker with access to a forwarded agent connection could possibly use
this issue to perform operations that should only be available locally,
such as adding tokens or using keys. (CVE-2026-73281)

It was discovered that OpenSSH's ssh client incorrectly handled concurrent
remote-forwarding operations. A remote attacker could possibly use this
issue to cause a use-after-free condition, resulting in a denial of service
or the execution of arbitrary code. (CVE-2026-73282)

It was discovered that OpenSSH's sshd server incorrectly applied the
restrict keyword from authorized_keys to tunnel forwarding requests. A
local attacker with an authorized key could possibly use this issue to
bypass intended tunnel forwarding restrictions. (CVE-2026-73283)


Update instructions

After a standard system update you need to restart OpenSSH to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute openssh-client –  1:10.2p1-2ubuntu3.6
openssh-server –  1:10.2p1-2ubuntu3.6
24.04 LTS noble openssh-client –  1:9.6p1-3ubuntu13.19
openssh-server –  1:9.6p1-3ubuntu13.19
22.04 LTS jammy openssh-client –  1:8.9p1-3ubuntu0.17
openssh-server –  1:8.9p1-3ubuntu0.17

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›